chore: Bump SixLabors.ImageSharp and SixLabors.ImageSharp.Drawing - #42
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps SixLabors.ImageSharp from 3.1.12 to 4.1.2 Bumps SixLabors.ImageSharp.Drawing from 2.1.7 to 3.1.2 --- updated-dependencies: - dependency-name: SixLabors.ImageSharp dependency-version: 4.1.2 dependency-type: direct:production update-type: version-update:semver-major - dependency-name: SixLabors.ImageSharp.Drawing dependency-version: 3.1.2 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
This one is blocked on licensing, not on code. ImageSharp 4.x and ImageSharp.Drawing 3.x enforce a Six Labors license key at build time. CI fails inside The version pairing in this PR is correct — Drawing 3.1.2 is the companion to ImageSharp 4.1.2, which is why the standalone #45 was closed. There is simply no way to make this build without a key. Options, in rough order of least effort:
Leaving this open pending that decision rather than closing it. |
|
Closing: the decision is to stay on ImageSharp 3.1.12 + Drawing 2.1.7. They build green, are not end-of-life, and remain free for this project — Six Labors only require a paid licence for a direct dependency in closed-source, for-profit software from a business over $1M USD annual revenue, which a GPL-3.0 Jellyfin plugin is not. The blocker in 4.x is the build-time key enforcement, not the licence terms themselves. #47 adds Reopen this if the calculus changes — for example if key enforcement is ever backported to 3.x, or if a security fix lands only on 4.x. |
|
Looks like these dependencies are no longer being updated by Dependabot, so this is no longer needed. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Updated SixLabors.ImageSharp from 3.1.12 to 4.1.2.
Release notes
Sourced from SixLabors.ImageSharp's releases.
4.1.2
What's Changed
Full Changelog: SixLabors/ImageSharp@v4.1.1...v4.1.2
4.1.1
What's Changed
Full Changelog: SixLabors/ImageSharp@v4.1.0...v4.1.1
4.1.0
What's Changed
New Contributors
Full Changelog: SixLabors/ImageSharp@v4.0.0...v4.1.0
4.0.0
What's Changed
... (truncated)
Commits viewable in compare view.
Updated SixLabors.ImageSharp.Drawing from 2.1.7 to 3.1.2.
Release notes
Sourced from SixLabors.ImageSharp.Drawing's releases.
3.1.2
What's Changed
Full Changelog: SixLabors/ImageSharp.Drawing@v3.1.1...v3.1.2
3.1.1
What's Changed
Full Changelog: SixLabors/ImageSharp.Drawing@v3.1.0...v3.1.1
3.1.0
What's Changed
New Contributors
Full Changelog: SixLabors/ImageSharp.Drawing@v3.0.0...v3.1.0
3.0.0
What's Changed
Full Changelog: SixLabors/ImageSharp.Drawing@v2.1.5...v3.0.0
Commits viewable in compare view.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)